-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
Closed
Labels
1. to developAccepted and waiting to be taken care ofAccepted and waiting to be taken care ofenhancement
Milestone
Description
Assume:
- A mobile user U using the Nextcloud App N that wants to view a video file in an external app
- A video app like VLC that you trust
- A mallware app EVIL that tries to hijack the url send from N to VLC
Because we are sending the link into the open basically we must assure:
- The link is read only
- The link is only valid for a limited amount of time (8 hours?)
- The link does not contain the users username and password
- Just a random generated token
Basically we'd need an endpoint where the app can say: "I want to have a link to read the file with fileID X". The endpoint will then generate a link that can be send to VLC.
This endpoint should be webdav since it already support range requests by default etc.
CC: @tobiasKaminsky
sunjam
Metadata
Metadata
Assignees
Labels
1. to developAccepted and waiting to be taken care ofAccepted and waiting to be taken care ofenhancement